Description
WordPress Plugin Menu Image is prone to an issue which allows the add-on of malicious scripts to the affected website, through the use of notice.php file. WordPress Plugin Menu Image version 2.6.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.0 or latest
References
Related Vulnerabilities
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-13950)
WordPress Plugin Shantz WordPress QOTD Cross-Site Request Forgery (1.2.2)
WordPress Plugin WP Ultimate Exporter Cross-Site Scripting (1.0)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-4893)
WordPress Plugin Lightbox Jquery Possible Remote Code Execution (0.24)